Develop a 6- to 7-page manual using the Security Standards, Policies, and Procedures Template with recommendations to management of security standards, polices, and procedures which should be implemented in your chosen organization.
Research and include the following:
REFER TO ADDITIONAL RESOURCES BELOW and the grading rubric.
Explain the importance to your organization of implementing security policies, plans, and procedures. Discuss how security policies, plans, and procedures will improve the overall security of the organization.
Recommend appropriate policies and procedures for:
Data classification policies and procedures (data isolation)
Non-disclosure Agreement policies and procedures
Strong authentication (password policies and procedures… and multi factor authentication)
Acceptable use of organizational assets and data
Employee policies (separation of duties/training)
Risk Management
Avoidance
Transference
Mitigation
Acceptance
Compliance examples that might affect your organization or others [Regulatory, Advisory, Informative]
HIPAA
NIST Cybersecurity Framework
Sarbanes/Oxley
GLBA
PCI DSS
Incident response (How should we prepare, and what should happen in each phase)
Preparation
Identification
Containment
Eradication
Recovery
Lessons learned (root cause analysis and action plan)
Auditing
Environmental/Physical
Administrative
From the text:
“Controls are implemented as administrative, logical, and physical. Administrative controls are also known as management controls and include policies and procedures. Logical controls are also known as technical controls and are implemented through technology. Physical controls use physical means to protect objects.”
Configuration (change management and system hardening)
